GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Arthur Hayes: Rising Oil Prices, AI-Related IPOs, and Trump's Anti-AI Rhetoric Could Pop the AI Bubble and Drag Down the Crypto Market

Odaily News, June 9th — BitMEX co-founder Arthur Hayes stated in his latest article "Reality Test" that if oil prices continue to rise due to the US-Iran conflict, it could trigger a collapse of the AI stock bubble and drag the entire crypto market down.Hayes said that if traffic restrictions in the Strait of Hormuz persist deep into the second quarter, spot prices for hydrocarbons and other key commodities could rise in the third quarter. If oil prices continue to climb and inflationary pressures impact the US midterm elections, Trump might pivot to a tough stance targeting data center construction, AI regulation, and taxation. Hayes believes the market could anticipate Trump limiting AI capital expenditure and taxing AI companies, thereby triggering the burst of the AI stock bubble.Hayes also noted that since November 2022, the scale of AI-related debt issuance has been approximately $1.5 trillion, and US M2 has increased by roughly the same amount during the same period. He believes the three factors that could pop the AI bubble include rising energy costs, the market's inability to absorb three major AI-related IPOs — namely SpaceX, Anthropic, and OpenAI — and Trump's shift to opposing AI. In terms of portfolio, Hayes stated that Maelstrom's stock portfolio holds significant positions in US-listed energy producers; he has sold AI-related stocks and offloaded non-core crypto assets, having dumped HYPE, NEAR, and WLD last week, as well as selling ZEC due to the Orchard Pool vulnerability. He still holds Bitcoin and ETH and will execute tactical short trades via derivatives.

ZEC Contract Positions on Hyperliquid Plunge 51.6% in Three Days, with $145 Million Positions Exiting Early

According to Hyperinsight’s monitoring, Zcash faces a theoretical risk of unlimited token supply due to a vulnerability in its Orchard zero-knowledge proof system. Negative public sentiment surrounding its “black-box” nature has continued to escalate and culminated in today’s concentrated outbreak.

A hacker organization has made over $14 million through token scams and X account hijackings

on-chain analyst Specter stated that the hijacking incidents of investor Keith Gill, Matt Furie, and WinRAR accounts on the X platform are all linked to the same hacker organization. This organization has accumulated over $14 million in profits by hijacking accounts to promote tokens and conducting cross-chain money laundering, with funds flowing through five chains: Solana, BNB Chain, Ethereum, Tron, and Hyperliquid.Specter claims the organization may also be connected to a $2.45 million wstETH phishing attack in 2024. The investigation found that hackers used compromised accounts to issue Pepe imitation tokens, incorporating a built-in 2% automatic fee mechanism to generate profits; related fund flows are associated with the bnbshare.fun platform and multiple Solana, Tron, and Ethereum addresses. Analysis also showed that several tokens (including USOR, VDOR, DROID, WCOR, UGOR) were used to inflate market caps before being dumped to zero.

Chainalysis Tracks THORChain Attack Source: Proficient Money Laundering Skills, Cross-Chain Fund Transfer Weeks Before Attack

Odaily Chainalysis posted on X platform, stating that prior to the THORChain theft, wallets suspected to be linked to the attacker had been transferring funds through Monero, Hyperliquid, and THORChain for several consecutive weeks. As early as late April, the attacker-associated wallets deposited funds into Hyperliquid positions via Hyperliquid and the Monero privacy bridge. These funds were subsequently converted to USDC and transferred to Arbitrum, then bridged to Ethereum. Some of the ETH was then moved to THORChain to stake as RUNE for a newly joined node, which is believed to be the source of the attack.Subsequently, the attacker bridged a portion of the RUNE back to Ethereum and split it into four chains. One chain went directly to the attacker, passing through intermediate wallets before transferring 8 ETH to the wallet that would ultimately receive the stolen funds, just 43 minutes before the attack. The funds from the other three chains flowed in reverse. Between May 14 and 15, these wallets bridged the ETH back to Arbitrum again, deposited it into Hyperliquid, and transferred it into Monero via the same privacy bridge, with the final transaction occurring less than 5 hours before the attack commenced. As of Friday afternoon, the stolen funds remain untouched, but the attacker has demonstrated sophisticated cross-chain money laundering capabilities. The Hyperliquid to Monero path may be the next move.

Euler takes over operations of HypurrFi's Mewler market, HypurrFi to gradually shut down and complete migration

Euler Finance announced it will take over the maintenance and operation of the Euler contract stack known as Mewler under HypurrFi on the Hyperliquid EVM. The relevant infrastructure is undergoing a smooth transition, with Clearstar Labs continuing to serve as the risk manager for the Prime, Yield, and Earn vaults. HypurrFi Scale and Pooled Markets are scheduled to gradually wind down and undergo orderly liquidation over the coming weeks. However, all existing markets remain solvent and fully operational, with no security vulnerabilities or emergency parameter adjustments.During the migration process, new borrowing functionality for some Pooled assets has been frozen, but HYPE, USDC, and USDT0 can still be used for liquidity provision to allow borrowers to gradually unwind their positions. Euler emphasized that its isolated lending architecture on HyperEVM will continue to serve as core infrastructure, jointly maintained by Euler and Clearstar Labs.The HypurrFi team stated that user deposits, positions, and collateral assets remain fully secure. This adjustment is an active strategic migration, not a security incident or protocol failure. According to the plan, Euler Prime and Yield markets will become the primary entry points for lending and yield markets on HyperEVM moving forward. The HypurrFi brand will be gradually phased out, with related support services closing after May 28. Full market liquidation is expected to be completed by July 15, 2026.HypurrFi also reminded users to be aware of risks and fraudulent links during the migration process, to operate only through official channels, and to use the built-in migration tools to transfer Pooled positions to Euler Prime or Yield markets.

ZachXBT: PolyArb is a fake prediction market product equipped with a wallet stealer.

On-chain investigator ZachXBT replied that PolyArb is a fake prediction market product whose website contains a wallet-stealing script. Previously, PolyArb claimed on X that the Hyperliquid HIP-4 outcome market achieved $6.15 million in daily BTC trading volume within 48 hours. William LeGate, Head of User Growth, questioned its claims regarding Polymarket’s fee structure. ZachXBT warned that replying to the relevant account could generate further exposure and increase the number of potential victims.

PeckShield: Attacker exploited low liquidity to trigger “suicidal” liquidations, causing Hyperliquid HLP to lose approximately $1.5 million within 24 hours

According to on-chain analyst PeckShield (@PeckShieldAlert), the attacker established a $15 million long position in $Fartcoin (totaling 145.24 million tokens) on Hyperliquid using four wallets. Subsequently, in a low-liquidity environment, the attacker deliberately triggered a “suicidal” liquidation, forcing activation of the ADL (Automatic Deleveraging) mechanism. As a result, the HLP liquidity pool was compelled to absorb toxic assets, generating bad debt and incurring approximately $3 million in paper losses. The HLP has lost roughly $1.5 million within the past 24 hours. PeckShield noted that the attacker likely executed cross-market hedging strategies in advance, meaning the actual net profit may significantly exceed the reported paper loss figure.